Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Is Portknocking "Real" Security?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
how does brutus aet2 works? »
« Black Viper is back! Yes,  
AuthorAll Replies


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

reply to Daniel
Re: Is Portknocking "Real" Security?

The concept of portknocking from the day's it was proposed using firewall logs changed into a "secret knock" thingie is like giving your neighbor a key to you cottage and trust him to protect it. Not only protect the "key"..but also your place. You do not know where he will store the key muchless when "he" enters your cottage if it was really his muddy feet in the buffer overflow.

If you are looking for peace of mind Security..the weighted scale is against portknocking..but if you are just after a new whistle and bell "feature" then go for it..it does not ADD anything to real security..it just throw another problem into the equation...no matter how secure you think you are doing it.

I will be standing in the hallway
»www.songlyrics.com/song-lyrics/O···534.html

"Knock three times
On the ceiling if you want me.
Mmm-hmm, twice on the pipe
If the answer is no."
--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:


2 edits
Your analogy is horribly flawed, Name Game. Nobody gets a "key" to the cottage. A "key" implies that a successful portknock yields a shell via SSH. It doesn't. All a successful portknock gives you is the ability to try one's hand against standard SSH security. No security layers are removed from the equation; one is just added.

Do you still think this is a problem?
--
dmiessler.com -- grep understanding knowledge
Forums » Up and Running » Security » Securityhow does brutus aet2 works? »
« Black Viper is back! Yes,  


Monday, 09-Nov 11:08:32 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [21] VoIP Over 3G Still Not Working For iPhone
· [15] Bill Would Force ISPs To Block Financial Scams
· [6] Clearwire To Get Another $1.5 Billion
· [4] Mediacom Hints At 50, 100 Mbps Speeds
Most people now reading
· Divorce advice... [General Questions]
· [WIN7] Which Services in Win 7 Have You Turned Off? [Microsoft Help]
· 60 Minutes piece on cyber security last night [Security]
· Framed for child porn 151; by a PC virus [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· My cat is reluctant to exercise. [General Questions]
· Why do they traumatize kids in Phys. Ed. in school? [Canadian Chat]
· Bell disconnection fee? WTF? [TekSavvy]
· [Rant] Brand New 'Jasper' Xbox360 - RRoD Hardware Failure [Rants, Raves, and Praise]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]